<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Phaas on CuraSec</title><link>https://curasec.metacog.co.kr/tags/phaas/</link><description>Recent content in Phaas on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 23 Sep 2026 15:27:03 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/phaas/index.xml" rel="self" type="application/rss+xml"/><item><title>EvilTokens PhaaS disrupted after enabling AI-assisted device code phishing</title><link>https://curasec.metacog.co.kr/insights/2026-09-23-unmasking-eviltokens-getting-to-the-root-of-device-code-phis/</link><pubDate>Wed, 23 Sep 2026 15:27:03 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-23-unmasking-eviltokens-getting-to-the-root-of-device-code-phis/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Device code phishing industrialization is a signal to audit whether OAuth device code flow is enabled in your Entra ID / identity provider — restrict it to only necessary clients and enforce conditional access policies that block token reuse from unexpected locations.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> EvilTokens was actively stealing tokens at scale via device code flow; hunt for anomalous device code authentication requests in your identity logs (Entra Sign-in logs, unified audit log) since at least early 2026, and tune detections for device code grants issued to unfamiliar device types or followed by token use from new geographies.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The Microsoft DCU-led disruption illustrates how AI-assisted PhaaS platforms are lowering the bar for credential and token theft campaigns; useful context for the next board or risk-committee briefing on evolving phishing sophistication.&lt;/li>
&lt;/ul></description></item></channel></rss>